performance-profiling
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze external data sources, including application source code and diagnostic logs provided by users. This creates a surface where malicious instructions embedded within the processed data could attempt to manipulate the agent's behavior.\n
- Ingestion points: The skill guides the agent to identify performance categories from user reports, traces, and logs, and to inspect code paths (SKILL.md).\n
- Boundary markers: No explicit delimiters or instructions are provided to the agent to distinguish between data and potential instructions within the analyzed traces or code.\n
- Capability inventory: The skill workflow involves identifying issues, reading reference files, inspecting code paths, and proposing fixes, which requires the agent to interpret and act on the provided data (SKILL.md).\n
- Sanitization: The instructions do not include steps for the agent to sanitize or validate the integrity of user-supplied code or performance logs before analysis.
Audit Metadata